Navigation

Get in touch
Logo
News

PKI & certificates

PKI and signatures with protected keys.

Certificates link identities to keys. We plan certificate hierarchies, protect CA and signing keys in the HSM and integrate issuance, renewal and revocation into your environment. For software releases, we develop a controlled signing process instead of freely available key files.

closeup photo of turned-on blue and white laptop computer — illustrative image
PKI and signing architecture · Planning and implementation by OTOKO®

Your brief for OTOKO®

What we take care of for you.

We define who may request, approve and issue certificates and which identity is confirmed in them. The root CA, issuing CA and status services are given separate tasks. Validity periods, renewal windows and revocation procedures are chosen to fit the users and devices. Automatic renewal also needs monitoring: a process that has started successfully is not yet a certificate installed on all target systems.

The possible scope of services

  • Plan root and issuing CAs with a trust and role model
  • Connect the CA or signing application through the supported interface
  • Configure certificate profiles, renewal and revocation information
  • Prepare key ceremonies and offline procedures
  • Link code-signing approvals to the delivery chain

We define the specific scope, your involvement and the acceptance criteria before the start.

Technology explained clearly

How we carry out the task.

01

The key stays protected, the application decides

The HSM protects a signing key within its intended boundary; it does not itself decide whether a software package should be approved for release. That is why we tie signing calls to identified applications, permissions and approvals. In code signing, the artifact and the approval are linked together, so that later changes are detectable. The CA software and the HSM provider must both support the algorithm and key access method in use. Trust stores, status checking and renewal are tested with representative counterparts.

02

Practicing revocation and recovery

A lost administrator card, expired certificates and a compromised issuing CA are different events. We create suitable procedures and test the agreed recovery path. Among other things, the acceptance test documents issuance, renewal, revocation and invalid requests. Existing certificate profiles, device classes and trust relationships help plan parallel operation during migration.

03

Microsoft AD CS, Java application or your own signing service

We check the integration supported by the respective product, for example through a CNG Key Storage Provider, PKCS #11 or a Java provider. An identical algorithm name alone does not guarantee compatibility: mechanisms, key attributes, padding and provider version must also match. For existing certificate authorities, we clarify whether a permitted key transfer is possible or whether a new CA with a transition phase is needed. The trust relationships of the connected systems are explicitly covered in the test.

04

Controlling code signing in the build pipeline

The pipeline should not permanently hold a freely usable production key. We separate the build from the signing approval, bind jobs to an identified system and define which artifacts may be signed with which key. Timestamps, proof of the artifact hash and logging are planned to fit the signature format. Here, an HSM is a protective component: reviewing the code and deciding on a release remain tasks of the development and release process.

05

Example: modernizing an existing enterprise PKI

An organization already manages certificates for devices, users and internal services. OTOKO® records certificate profiles, distribution and trust chains, and first tests the intended HSM integration outside production. We then plan the switch-over, including renewal, revocation information and fallback boundaries. Before handover, specific counterparts are tested: an issued certificate is only a success once login, service access or signature verification works in the intended system.

Meeting room at the OTOKO® Cologne office

A verifiable result

What you keep working with.

  1. PKI and signing architecture
  2. Implemented integration with test evidence
  3. Ceremony and operations manual

The handover brings together implementation and documentation. Together, we review the agreed cases and record any remaining tasks.

Before the first step

Your questions about PKI & certificates.

Does the existing PKI have to be replaced?

Not automatically. We check the HSM integration, existing keys and trust chains. A gradual extension or a parallel hierarchy can be more suitable than a complete replacement.

Does this make every signature a qualified one?

No. An HSM alone does not produce a qualified electronic signature. For that, the specific service, the procedure and the relevant requirements must be checked separately.

Does an HSM also make sense for an offline root CA?

Protecting a root key used over the long term can be a reason for it. However, the concept also includes separate custody, defined activation, a documented ceremony procedure and a tested recovery path. The device alone does not replace these procedures.

Can you integrate Microsoft AD CS?

We review and implement the integration through a provider supported for the combination in use. The Windows and CA versions, HSM firmware, client library and required algorithm are decisive. Existing keys require a separate migration review.

Does the HSM protect against tampered software being signed?

It protects the key material within its intended scope. Whether an artifact may be released is decided by the signing process. That is why we combine the HSM integration with identities, restricted permissions and traceable approvals.

What does acceptance of a PKI integration include?

We agree on tests for issuance, use, renewal and revocation, as well as for invalid requests. Recovery and behavior in the event of an HSM failure are also covered. Scope and representative counterparts are defined in advance.

Your project

Which task would you like to solve?

Describe your situation and the desired result. The selected service will be included in the contact request.

Request this service

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.